MD-CERT it is the center of computer security incidents analysis operating as important element of the national research and educational networking infrastructure. MD-CERT is engaged in gathering, registration and analyzing of the facts of all computer incidents (i.e. attempts or the facts of infringements of the owner of the information, or various attacks within network or from the Internet) concerning to the network resources located on the territory of Moldova, but fist of all that are affecting users of the Research and Educational network .
Any information about computer incidents, references to useful resources in the field of protection of information technologies, wishes, will be closely considered and as far as possible taken under consideration by Security Teams. MD-CERT guarantees confidentiality of all sent information about incidents. MD-CERT is the noncommercial structure and according to its status is not engaged in the any activity connected with advertising, promotion of those or other decisions and techniques, an exchange of banners, development of commercial projects on information protection, etc.
Realization of CERT in Moldova was initialized by NATO project “Creation of Infrastructure for CERTs in Belarus, Moldova, Ukraine and their Initial Operation” in for operation in Research and Educational networking segment of Moldova.
Specific features of MD-CERT organization and functioning as a part of RENAM networking infrastructure:
Our Team started activity at 2006, thanking a NATO project that was targeted to set up CERT in Moldova, Ukraine and Belarus.
For increasing security and registration dangerous incidents in the RENAM’s network was created CERT (Computer Emergency Response Team). This is group of specialist who should engage in registration these incidents in the network and assist in eliminating the incidents.
Collecting of the information about the incidents should be done by 3 methods
In the first case the incident is fixing automatically with help of many software programs and hardware equipment, mostly with help of such protocols as ICMP SNMP. There is a much of software for monitoring the system for example (Nagios and NetIIS). These programs are comfortable and well tested, but not always are suitable to all requests of monitoring. Also exists the necessity for CERT officers to add some modules for monitoring system.
Fixation of the incidents vie automatic facility of monitoring helps to define existing of the incidents and even avoid the incident automatically. Besides this the automatic system helps to define statistics and consequence of the incidents and make action to avoid it.
The incident also can be examined by CERT officer if the incident is registered and sent to CERT officer vie one of this methods